Re: xprobe 0.2

From: Ryan Permeh (ryan@eEye.com)
Date: 10/28/01


Message-ID: <012201c15fde$b0438d00$1e00a8c0@eCompany.gov>
From: "Ryan Permeh" <ryan@eEye.com>
To: "nobody" <pentester@yahoo.com>, <pen-test@securityfocus.com>
Subject: Re: xprobe  0.2
Date: Sun, 28 Oct 2001 10:30:58 -0800

the codebases are exactly the same(or should be). kernels between
workstation and server should be the same. The main difference is in
tuning, a few registry checks, and sometimes more software is installed. If
you can use theese techniques to id the different systems, you may have a
chance. try looking at things like #of syns before dropping, perhaps
distribution of ISN's, or something along those lines.
Signed,
Ryan Permeh
eEye Digital Security Team
http://www.eEye.com/Retina -Network Security Scanner
http://www.eEye.com/Iris -Network Traffic Analyzer
http://www.eEye.com/SecureIIS -Stop Known and Unknown IIS Vulnerabilities

----- Original Message -----
From: "nobody" <pentester@yahoo.com>
To: <pen-test@securityfocus.com>
Sent: Friday, October 26, 2001 6:25 AM
Subject: xprobe 0.2

> All,
>
> the new xprobe 0.2 works well - as far as it goes.
> But - does anyone know if there is sufficient
> difference between the tcp/ip signature of an NT
> WORKSTATION and an NT SERVER OS.
>
> Problem:
>
> I need to (without making a windows connection via SMB
> using pgms like gettype, winmsd, winffingerprint
> etc..)
> determine which Windows machines are running NTSERVER
> OS.
>
> Does anyone know or think the the tcp/udp packet
> response from the NT SERVER will be different enough
> from the NT WORKSTATION - so that I can tell them
> apart. again - i cannot use the normal windows
> connections to do this (no port 139 connections).
>
> If there are any difference in the packet response -
> then I could add an NT SERVER (does not matter if it
> is NT or W2K) to the signature file for xprobe 0.3 ??
>
> any help ?
>
> thanks
>
>
> __________________________________________________
> Do You Yahoo!?
> Make a great connection at Yahoo! Personals.
> http://personals.yahoo.com
>
> --------------------------------------------------------------------------

--
> This list is provided by the SecurityFocus Security Intelligence Alert
(SIA)
> Service. For more information on SecurityFocus' SIA service which
> automatically alerts you to the latest security vulnerabilities please
see:
> https://alerts.securityfocus.com/
>
>

---------------------------------------------------------------------------- This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/



Relevant Pages

  • Re: Paradigms II
    ... > are not about trying to circumvent security. ... > (server or workstation); however, they can be easily adapted to any other ... > to have at least a vague idea what security, and a secure environment, ...
    (comp.security.misc)
  • Re: Event ID 5719: No Windows NT or Windows 2000 Domain Controller is available for domain .
    ... In my experience what you have done with security policy should ... The workstation gets its networking information from DHCP that, ... updates DNS. ... I don't believe the problem to be at the server end though. ...
    (microsoft.public.win2000.security)
  • Re: "Classic logon" screen in XP does not remeber the user name
    ... I went to the workstation. ... does not show up on the server when I log onto the ... When you are done configuring Local Security Policy run the ... "Local security policy does not allow interactive login on this ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Local Security Policy Locked (or something?)
    ... at one time I may have been booting the server ending up ... for the local workstation. ... Failed to open IPsec policy storage Access is ... or not a given security setting is defined in group policy. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Cant see other computers/nodes on network!
    ... so when you are on a workstation and you go to \\knight-tech\ you don't ... on the difference between some of the products (Server, XP Pro, XP Home, ... Print, Streaming Media and SECURITY). ... the first thing I see is that the server isn't using the same DNS server ...
    (microsoft.public.windows.server.networking)